Denial-of-Service Vulnerability in Zoho ManageEngine ADSelfService Plus
CVE-2023-28342

7.5HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
5 April 2023

What is CVE-2023-28342?

A vulnerability in Zoho ManageEngine ADSelfService Plus prior to version 6218 allows unauthorized users to perform Denial-of-Service (DoS) attacks via the Mobile App Authentication API. This flaw can disrupt services and affect availability, emphasizing the need for timely updates and effective security measures to protect against such potential exploits. Organizations are advised to upgrade to the latest version to mitigate risks associated with this vulnerability.

References

EPSS Score

85% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.